> ## Documentation Index
> Fetch the complete documentation index at: https://readme.amana-dev.com/llms.txt
> Use this file to discover all available pages before exploring further.

# API Guide

> How the Amana API is organized, how to authenticate, and how every endpoint page is laid out.

The Amana API is a REST API that returns JSON. Use it to sign users in, onboard and verify them, move money, trade, and read market data.

<Warning>
  IP whitelisting is mandatory for business access. Amana rejects requests from IP addresses that are not whitelisted. Submit your server IPs during [onboarding](/revamp/partner-onboarding-checklist).
</Warning>

## Base URL

```text theme={null}
‹base URL›
```

Confirm the base URL for each environment with Amana before you send requests.

## Authentication comes first

Most endpoints need an access token.

1. Call **Log in** with the user's email and password to get an `access_token` and a `refresh_token`.
2. Send the access token in the `Authorization` header on every request.
3. When the access token expires, call **Refresh access token** to get a new one.

```bash theme={null}
Authorization: Bearer <access_token>
```

## API groups

| Group | What it's for |
| - | - |
| Authentication | Log in, refresh tokens, log out, reset passwords, and manage passkeys. |
| Onboarding & KYC | Create accounts step by step and collect verification details and documents. |
| Funding | Deposit, withdraw, transfer, and manage saved payment methods. |
| Trading | Place, modify, and close orders and positions. |
| Account & reporting | Manage the profile and trading accounts, and get history and statements. |
| Nafath sign-in | Sign users in with their Saudi national identity through Nafath. Only for users in Saudi Arabia. |
| UAE Pass sign-in | Sign users in with their UAE digital identity through UAE Pass. Only for users in the UAE. |
| Market data | Find instruments and get prices, candles, and market events. |
| Watchlists & alerts | Save favorite instruments and get notified at a price. |
| Notifications | List in-app notifications and register devices for push. |
| Other | App content, promotions, and support tools. |

## How each endpoint page is laid out

Every endpoint page follows the same template:

* **Title and purpose:** what the endpoint does and when to use it, in one or two sentences.
* **Request and response:** each field with its type and description. Only request fields are marked as required. Each page shows a sample response.
* **Possible Errors:** each possible error, its cause, and what to do, shown below the response.

See [Error codes](/revamp/error-codes) for the full list of errors.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.